CVE-2014-8182

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/01/2020
Last modified:
09/01/2020

Description

An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openldap:openldap:2.4:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*